SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-12702

MEDIUM · CVSS 4.9 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Affected versions of Octopus Deploy have insufficient validation on project trigger actions, enabling unauthorized users to initiate deployments without proper permissions. This vulnerability poses a significant risk of unauthorized access and potential disruption to deployment processes. Organizations using Octopus Deploy should prioritize addressing this issue to safeguard their deployment environments.

CVE
CVE-2026-12702
Severity
MEDIUM
CVSS
4.9
EPSS
0.19%

Original NVD Description

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

Related CVEs

Other vulnerabilities affecting the same vendor(s)